Notes:

  • COSO Framework (Committee of Sponsoring Organizations): The global gold standard for internal controls. It consists of five interrelated components:
    1. Control Environment: The tone at the top, ethics, and organizational structure.
    2. Risk Assessment: Identifying and analyzing risks that could prevent the achievement of objectives.
    3. Control Activities: Policies and procedures (e.g., approvals, reconciliations, segregation of duties) to mitigate risks.
    4. Information & Communication: Ensuring relevant information flows up, down, and across the organization.
    5. Monitoring Activities: Ongoing evaluations and separate assessments to determine if controls are working.
  • Sarbanes-Oxley (SOX) Section 404:
    • Management Assessment: CEOs and CFOs must certify the effectiveness of internal controls over financial reporting (ICFR).
    • Auditor Attestation: External auditors must independently attest to management’s assessment (for large accelerated filers).
    • Material Weaknesses: A deficiency where there is a reasonable possibility that a material misstatement of financial statements will not be prevented or detected. Must be disclosed publicly.
  • Segregation of Duties (SoD): A fundamental control principle where incompatible duties are separated (e.g., the person authorizing a payment cannot be the same person recording it or holding the cash). This prevents fraud and error.
  • Continuous Monitoring: Moving from periodic testing to real-time monitoring using data analytics and automated controls.